# Dalatigue

*/Startups/Dalatigue*

## Startup Overview

Security engineers manage a sprawl of access controls across varied cloud environments, routinely relying on fragmented native cloud dashboards and manual spreadsheet audits to track user and machine privileges. This platform normalizes multi-cloud Identity and Access Management (IAM) permissions into a single, unified graph. It automatically ingests access policies from across the infrastructure and maps the exact, explorable relationships between identities, roles, and target resources.

Legacy CSPM scanners typically output static compliance alerts without context, leaving teams to manually trace attack paths. Instead, this solution provides a zero-configuration deployment that connects directly to cloud provider APIs to instantly visualize complex access chains and highlight excessive permissions. The service prices strictly by the number of identity risks actually remediated, directly aligning infrastructure cost with concrete security outcomes.

## Startup Founding Hypothesis

**Approach**: that normalizes multi-cloud IAM permissions into a unified graph
**Competitors**:
- [Manual Spreadsheet Audits](/Competitors/Manual_Spreadsheet_Audits)
- [Native Cloud Dashboards](/Competitors/Native_Cloud_Dashboards)
- [Legacy CSPM Scanners](/Competitors/Legacy_CSPM_Scanners)
**Differentiator2x2**: a zero-configuration deployment that prices strictly by remediated identity risks

## Startup Solution Coordinate

**Solution**: [Identity Risk Graph](/Software/Identity_Risk_Graph)

## Startup Position2x2

```mermaid
quadrantChart
    title Multi-Cloud IAM Permission Tools
    x-axis "Heavy Configuration" --> "Zero-Configuration"
    y-axis "Fixed Licensing Fee" --> "Prices by Remediated Risk"
    quadrant-1 "Frictionless Value"
    quadrant-2 "High-Touch Remediation"
    quadrant-3 "Legacy Sunk Costs"
    quadrant-4 "Free / Bundled Tools"
    Manual Spreadsheet Audits: [0.10, 0.10]
    Legacy CSPM Scanners: [0.20, 0.35]
    Native Cloud Dashboards: [0.45, 0.15]
    Dalatigue: [0.90, 0.90]
```

## Startup Offer

**Proof**:
- Targeting zero manual audit hours for quarterly cross-cloud IAM compliance reviews.
- Aims to safely revoke 80% of standing privileged access across combined AWS and GCP footprints without application downtime.
- Designed to map multi-cloud trust relationships and highlight toxic combinations within 24 hours of zero-configuration deployment.
**Tiers**:
- Name: Pay-As-You-Go · Price: ~$15–$35 per remediated identity risk · Inclusions: Zero-configuration deployment mapping up to 3 cloud environments, generating the unified multi-cloud IAM graph, with billing triggered strictly when an over-privileged account or standing permission is successfully right-sized.
- Name: Committed Volume · Price: ~$12,000–$25,000/yr · Inclusions: Pre-purchased block of up to 1,500 remediations across unlimited cloud environments, plus intended automated compliance reporting and exports designed for SOC2 evidence collection.
- Name: Enterprise Graph · Price: ~$35k–$60k/yr · Inclusions: Unlimited read-only IAM graph generation, custom remediation capping, intended SAML SSO integration, and designed ITSM ticketing workflows for manual approval routing.
**Guarantee**: Billing is strictly tied to successful right-sizing; if an applied IAM remediation breaks a verified production workload and requires a rollback within 7 days, that remediation charge is automatically refunded.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: Automated IAM changes might break our active production workloads. Rebuttal: The platform is designed to simulate all proposed permission changes against 30 days of historical access logs before actively applying any restrictions.
- Objection: We already have native cloud posture scanners. Rebuttal: Native tools stop at the single-cloud boundary; this normalizes complex cross-cloud trust relationships into one unified graph.
- Objection: Security deployment requires heavy configuration and write-access approvals. Rebuttal: The zero-configuration setup is designed to use read-only cross-account roles to build the initial graph, requiring write access only when you are ready to authorize a remediation.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Authoritative and precise, defined by a strict intolerance for ambiguity
**Tagline**: Remediate multi-cloud identity risks with unified access mapping
**Icon Concept**: Keycard
**Palette Intent**: electric-signal
**Visual Identity**: Deep charcoal and vivid cyan anchor sharp, monospaced typography, highlighting the strict boundaries of multi-cloud access control.
**Archetype Reference**: the-ruler

## Startup Buyer Chain

**Chain**: Dalatigue -> Cloud Security Engineer -> Enterprise Engineering Organization
**Gtm Motion**: Acquires users through a zero-configuration deployment that generates an immediate multi-cloud IAM risk graph. Expands revenue strictly as security teams execute fixes, charging only when a specific over-provisioned identity or access risk is successfully remediated.
**Agent Channel**: Intended for publication in the Model Context Protocol (MCP) registry and LangChain tool directories, exposing a structured IAM query endpoint for autonomous security agents to map and analyze cloud permission graphs.
**Primary Channel**: AWS and Google Cloud Marketplaces, where DevSecOps practitioners search for zero-config IAM auditing applications to attach to their existing cloud environments.

## Startup Customer Journey

```mermaid
flowchart LR; A[AWS Marketplace] --> B[Read-Only Cross-Account Role]; B --> C[Multi-Cloud IAM Graph]; C --> D[Historical Access Log]; D --> E[Identity Risk Remediation]; E --> F[SOC2 Compliance Report];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day read-only deployment pilot: Aiming to successfully map all multi-cloud trust relationships and highlight toxic combinations using zero-configuration setup without requiring write access.
- 30-day active remediation pilot: Targeting the execution of 50 simulated permission changes against historical logs, followed by live right-sizing with zero 7-day rollback requests.
**Target Metrics**:
- Target: 80 percent reduction in standing privileged access across combined multi-cloud footprints
- Aim: 24 hours to generate the initial unified multi-cloud IAM graph using only read-only cross-account roles
- Target: 0 manual audit hours required for quarterly cross-cloud IAM compliance evidence collection
- Aim: 100 percent simulation success rate against 30 days of historical access logs prior to actively applying restrictions
**Target Case Studies**:
- Mid-market SaaS operating across AWS and GCP: Aiming to map toxic cross-cloud trust combinations and right-size standing privileged access without disrupting active production workloads.
- Growth-stage fintech preparing for SOC2: Target case study demonstrating the automation of quarterly cross-cloud IAM compliance reviews to eliminate manual audit hours.
- Large enterprise scaling a multi-cloud footprint: Targeting the transition from standing privileges to strictly usage-metered remediations, proving zero-configuration deployment within 24 hours.
**Testimonial Targets**:
- Cloud Security Architect: Validating that the historical access log simulation accurately prevents production application breakage before IAM changes are applied.
- VP of Engineering: Expressing confidence that billing is strictly tied to successful, right-sized account remediations rather than arbitrary platform deployment counts.
- Chief Information Security Officer: Confirming the unified multi-cloud IAM graph effectively translates complex AWS and GCP trust relationships into clear, SOC2-ready evidence.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Customers refuse to execute remediation recommendations due to fear of breaking production applications, resulting in zero revenue under the pay-per-fix pricing model. · Mitigation Status: in-progress
- Severity: high · Description: Major cloud providers abruptly deprecate or heavily rate-limit the APIs required to map native IAM permissions, blinding the normalization engine. · Mitigation Status: unmitigated
- Severity: high · Description: The zero-configuration deployment fails in complex enterprise environments with heavily customized network topologies, blocking initial onboarding. · Mitigation Status: in-progress
- Severity: moderate · Description: Native cloud providers introduce cross-cloud IAM mapping capabilities into their default security dashboards at no additional cost. · Mitigation Status: unmitigated

## Startup Competitors

- [Manual Spreadsheet Audits](/Competitors/Manual_Spreadsheet_Audits) — Status Quo
- [Native Cloud Dashboards](/Competitors/Native_Cloud_Dashboards) — Incumbent Tools
- [Legacy CSPM Scanners](/Competitors/Legacy_CSPM_Scanners) — Incumbent
- [CyberArk Ermetic](/Competitors/CyberArk_Ermetic) — CIEM Provider
- [Sonrai Security](/Competitors/Sonrai_Security) — Identity Graph
- [Palo Alto Prisma](/Competitors/Palo_Alto_Prisma) — Platform Suite

## Startup Solution Stack

- [Identity Remediation Service](/Services/Identity_Remediation_Service) — Service-as-Software
- [IAM Normalization Agent](/Agents/IAM_Normalization_Agent) — Agent
- [Permission Graph Engine](/Software/Permission_Graph_Engine) — Software
- [Cross-Cloud Identity API](/Software/Cross-Cloud_Identity_API) — Software
- [Zero-Config Deployment SDK](/Software/Zero-Config_Deployment_SDK) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the architect of a hardened perimeter instead of a firefighter for over-privileged accounts
- **Want**: to right-size multi-cloud IAM permissions without breaking production workloads
- **Identity**: the Cloud Security Lead managing AWS and GCP environments
**Plan**:
- Step: Connect · Detail: Deploy read-only cross-account roles to map your multi-cloud trust relationships in 24 hours.
- Step: Validate · Detail: Review the unified graph to identify over-privileged accounts and simulate the impact of right-sizing.
- Step: Remediate · Detail: Approve automated permission tightening and pay only for risks that are successfully closed.
**Guide**:
- **Empathy**: Does your IAM audit process still rely on cross-referencing CSV exports from different cloud consoles?
**Problem**:
- **Villain**: standing privileges
- **External**: Manual spreadsheet audits fail to capture toxic combinations across AWS IAM roles and GCP Service Accounts
- **Internal**: You feel anxious every time an engineer leaves, wondering which cross-cloud backdoors remain open
- **Philosophical**: Cloud infrastructure was built for elastic scale, not permanent over-privileged access.
**Success**: Your multi-cloud environment reaches a state of least-privilege with zero manual audit hours and 80% less standing access.
**One Liner**: Fragmented cloud permissions cost security teams hundreds of audit hours. Dalatigue maps and right-sizes multi-cloud IAM risks so you can eliminate over-privileged accounts without breaking production.
**Positioning**:
- **So That**: eliminate cross-cloud identity risks with zero configuration and usage-based pricing
- **Unlike**: Native cloud posture scanners
- **For Whom**: Cloud Security Leads at multi-cloud organizations
- **Category**: Multi-cloud IAM Governance
**Call To Action**:
- **Direct**: Fix identity risks
- **Transitional**: View unified IAM graph
**Failure Stakes**:
- Quarterly compliance audit failure
- Lateral movement during a breach
- Application downtime from manual IAM errors
**Transformation**:
- **To**: governing access through automated remediation instead of manual audits
- **From**: a security lead buried in AWS and GCP console tabs
**Controlling Idea**: Identity security must be measured by risks remediated, not alerts generated.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Fragmented cloud permissions cost security teams hundreds of audit hours. Dalatigue maps and right-sizes multi-cloud IAM risks so you can eliminate over-privileged accounts without breaking production.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: f81c39c1c1d4125f

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Multi-cloud IAM Governance for Cloud Security Leads at multi-cloud organizations. Unlike Native cloud posture scanners — eliminate cross-cloud identity risks with zero configuration and usage-based pricing.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: d32f08c9bb3ea64e

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Manual spreadsheet audits fail to capture toxic combinations across AWS IAM roles and GCP Service Accounts
Solution: Fragmented cloud permissions cost security teams hundreds of audit hours. Dalatigue maps and right-sizes multi-cloud IAM risks so you can eliminate over-privileged accounts without breaking production.
Customer: Cloud Security Leads at multi-cloud organizations
Unlike: Native cloud posture scanners
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 3c9de3e75dc6e015

## Startup Token M E D D P I C C

**Pain**: Manual spreadsheet audits fail to capture toxic combinations across AWS IAM roles and GCP Service Accounts
**Metrics**: Target: Your multi-cloud environment reaches a state of least-privilege with zero manual audit hours and 80% less standing access.
**Rendered**: Pain: Manual spreadsheet audits fail to capture toxic combinations across AWS IAM roles and GCP Service Accounts
Economic buyer: Cloud Security Engineer
Metrics: Target: Your multi-cloud environment reaches a state of least-privilege with zero manual audit hours and 80% less standing access.
Competition: Native cloud posture scanners
**Mechanism**: spine-derived-v1
**Competition**: Native cloud posture scanners
**Economic Buyer**: Cloud Security Engineer
**Vocab Fingerprint**: adac83fcefcee941

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Multi-cloud IAM Governance for Cloud Security Leads at multi-cloud organizations

Cloud Security Leads at multi-cloud organizations — Manual spreadsheet audits fail to capture toxic combinations across AWS IAM roles and GCP Service Accounts Fragmented cloud permissions cost security teams hundreds of audit hours. Dalatigue maps and right-sizes multi-cloud IAM risks so you can eliminate over-privileged accounts without breaking production.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: f62bef129c897f97

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Multi-cloud IAM Governance. Fragmented cloud permissions cost security teams hundreds of audit hours. Dalatigue maps and right-sizes multi-cloud IAM risks so you can eliminate over-privileged accounts without breaking production. Serves Cloud Security Leads at multi-cloud organizations.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: f51987b4d35f66dd

## Neighborhood

### Candidate solutions

- [Source Heavy Plate Welders](/Problems/Source_Heavy_Plate_Welders) — candidate solution for · Problems

### What it offers

- [Identity Risk Graph](/Software/Identity_Risk_Graph) — offers · Software

### Composed of

- [Permission Graph Engine](/Software/Permission_Graph_Engine) — composes · Software
- [Identity Remediation Service](/Services/Identity_Remediation_Service) — composes · Services
- [IAM Normalization Agent](/Agents/IAM_Normalization_Agent) — composes · Agents
- [Cross-Cloud Identity API](/Software/Cross-Cloud_Identity_API) — composes · Software
- [Zero-Config Deployment SDK](/Software/Zero-Config_Deployment_SDK) — composes · Software

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Competitors

- [Palo Alto Prisma](/Competitors/Palo_Alto_Prisma) — competes with · Competitors
- [Manual Spreadsheet Audits](/Competitors/Manual_Spreadsheet_Audits) — competes with · Competitors
- [Native Cloud Dashboards](/Competitors/Native_Cloud_Dashboards) — competes with · Competitors
- [Legacy CSPM Scanners](/Competitors/Legacy_CSPM_Scanners) — competes with · Competitors
- [CyberArk Ermetic](/Competitors/CyberArk_Ermetic) — competes with · Competitors
- [Sonrai Security](/Competitors/Sonrai_Security) — competes with · Competitors

### Similar Startups

- [Accirm](/Startups/Accirm) — similar · Startups
- [Unitecrown](/Startups/Unitecrown) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Aegispark](/Startups/Aegispark) — similar · Startups
- [Domill](/Startups/Domill) — similar · Startups
- [Permoster](/Startups/Permoster) — similar · Startups
- [Aspenmere](/Startups/Aspenmere) — similar · Startups
- [Zenithember](/Startups/Zenithember) — similar · Startups
- [Novia](/Startups/Novia) — similar · Startups
- [Basisconsole](/Startups/Basisconsole) — similar · Startups
- [Incisive Software](/Startups/Incisive_Software) — similar · Startups
- [Weldedrock](/Startups/Weldedrock) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Direridian](/Startups/Direridian) — similar · Startups
- [Consolidatesphere](/Startups/Consolidatesphere) — similar · Startups
- [Posept](/Startups/Posept) — similar · Startups
- [Accault](/Startups/Accault) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Archos](/Startups/Archos) — similar · Startups
